In findParam of HevcUtils.cpp there is a possible out of bounds read due to a missing bounds check. This could lead to l
Out-of-bounds Read vulnerability in Delta Electronics DOPSoft.This issue affects DOPSoft: All Versions.
An out of bounds read vulnerability exists in the way OpenImageIO version v2.3.19.0 processes string fields in TIFF imag
Improper boundary check in sflvd_rdbuf_bits of libsflvextractor prior to SMR Apr-2022 Release 1 allows attackers to read
xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protoc
xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protoc
An information disclosure vulnerability exists in the Ethernet/IP UDP handler functionality of EIP Stack Group OpENer 2.
Buffer Over-read in audio driver while using malloc management function due to not returning NULL for zero sized memory
Out of bounds reads while parsing NAN beacons attributes and OUIs due to improper length of field check in Snapdragon Au
Out of bound reads might occur in while processing Service descriptor due to improper validation of length of fields in
Buffer over read can happen in video driver when playing clip with atomsize having value UINT32_MAX in Snapdragon Auto,
An issue was discovered in the xcb crate through 2021-02-04 for Rust. It has a soundness violation because there is an o
The WPG plugin before 3.1.0.0 for IrfanView 4.57 has a Read Access Violation on Control Flow starting at WPG!ReadWPG_W+0
A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read v
A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read v
A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read v
A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1 in Nef_S2/SNC_
Out-of-bounds Read vulnerability in iscsi_snapshot_comm_core in Synology DiskStation Manager (DSM) before 6.2.3-25426-3
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.4 and iPadOS 14.4. A r
Delta Industrial Automation CNCSoft ScreenEditor Versions 1.01.28 (with ScreenEditor Version 1.01.2) and prior are vulne
GattLib 0.3-rc1 has a stack-based buffer over-read in get_device_path_from_mac in dbus/gattlib.c.
In p2p_process_prov_disc_req of p2p_pd.c, there is a possible out of bounds read and write due to a use after free. This
FATEK Automation WinProladder Versions 3.30 and prior are vulnerable to an out-of-bounds read, which may allow an attack
The DNS feature in InterNiche NicheStack TCP/IP 4.0.1 is affected by: Buffer Overflow. The impact is: execute arbitrary
libmobi is vulnerable to Out-of-bounds Read
There is an Out-of-bounds memory access in Huawei Smartphone.Successful exploitation of this vulnerability may cause pro
Buffer over-read while UE process invalid DL ROHC packet for decompression due to lack of check of size of compresses pa
An out of bounds read can happen when processing VSA attribute due to improper minimum required length check in Snapdrag
The affected product is vulnerable to an out-of-bounds read, which may allow an attacker to obtain and disclose sensitiv
Possible buffer over-read while parsing quiet IE in Rx beacon frame due to improper check of IE length in received beaco
Possible buffer over read while processing P2P IE and NOA attribute of beacon and probe response frames due to improper
An issue was discovered in the fltk crate before 0.15.3 for Rust. There is an out-of bounds read because the pixmap cons
Potential out of bound read exception when UE receives unusually large number of padding octets in the beginning of ROHC
Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon
Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon
Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon
Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon
Buffer over read while processing MT SMS with maximum length due to improper length check in Snapdragon Auto, Snapdragon
Mutt 1.11.0 through 2.0.x before 2.0.7 (and NeoMutt 2019-10-25 through 2021-05-04) has a $imap_qresync issue in which im
Improper validation of the length field of LLDP-MED TLV in userdisk/vport_lldpd in Moxa Camera VPort 06EC-2V Series, ver
Improper validation of the length field of LLDP-MED TLV in userdisk/vport_lldpd in Moxa Camera VPort 06EC-2V Series, ver
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE16().
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ApplyFilter().
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE24().
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ShiftBytes().
A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkVerifyAndAssign.
A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkAssignData. The h
CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Read.
A flaw was found in the way CHACHA20-POLY1305 was implemented in NSS in versions before 3.55. When using multi-part Chac
An issue was discovered in Pillow before 8.2.0. There is an out-of-bounds read in J2kDecode, in j2ku_graya_la.
Frequently Asked Questions
What is CWE-125?
CWE-125 (Out-of-bounds Read) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-125?
There are 10,972 CVE records associated with CWE-125 in our database. Of these, 717 are critical severity, 3828 are high severity, and 4120 are medium severity.
How can I protect against CWE-125 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-125 using AI-powered security agents.
Detect CWE-125 Vulnerabilities
CyberStrike's AI agents automatically detect out-of-bounds read vulnerabilities across your infrastructure.
Get Started